Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27278 | A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect 4.1 allows an unauthenticated attacker to exfiltrate arbitrary files to an attacker-controlled server. TecConnect 4.1 is considered end-of-life as of December 2023. Users are advised to upgrade to TecCom Connect 5. |
Tue, 09 Sep 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Teccom
Teccom tecconnect |
|
| Vendors & Products |
Teccom
Teccom tecconnect |
Tue, 09 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Sep 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect 4.1 allows an unauthenticated attacker to exfiltrate arbitrary files to an attacker-controlled server. TecConnect 4.1 is considered end-of-life as of December 2023. Users are advised to upgrade to TecCom Connect 5. | |
| Title | XML External Entity Injection in TecConnect 4.1 | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: BLSOPS
Published:
Updated: 2025-09-09T15:14:59.774Z
Reserved: 2025-09-09T14:41:44.314Z
Link: CVE-2025-10183
Updated: 2025-09-09T15:14:53.816Z
Status : Deferred
Published: 2025-09-09T15:15:32.540
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-10183
No data.
OpenCVE Enrichment
Updated: 2025-09-09T21:31:06Z
EUVD